Blog

Practical insights on penetration testing, compliance, AI security and human risk.

2026-08-26

71% of reported incidents hit one sector — what the concentration in Romania's national cyber report means for financial entities

Romania's DNSC activity report for 2025, approved by CSAT Decision no. 117 of 7 August 2026, shows an unusual concentration: 71.09% of incidents reported across the analysed sectors hit banking, 10.8% postal and courier services, and 6.34% financial market infrastructures. What that means in practice for banks, non-bank lenders, payment institutions and logistics operators under NIS 2 and DORA.

Read →
2026-08-19

Romania's DNSC 2025 report — ransomware up 153%, and what the numbers say about your security priorities

The Romanian national cyber security authority's 2025 activity report, approved by CSAT Decision no. 117 on 7 August 2026, records 25.3 million security events, a 153% rise in ransomware and a 353% rise in account compromise — while brute-force incidents fell 72.7%. The contrast between those figures tells you exactly where to invest in 2026.

Read →
2026-08-19

Phishing is up 70.6% in Romania — what that means for your simulation programme

DNSC recorded 4,975 phishing incidents in Romania in 2025, up 70.6% year on year, and named phishing the primary attack vector. Meanwhile brute-force incidents fell 72.7%. The technical controls are working; the human vector is not. Here is what the national figures should change about the frequency, scenarios, metrics and documentation of your phishing simulation programme.

Read →
2026-08-19

Medusa ransomware hits 500 critical infrastructure targets — what the updated FBI/CISA advisory means for your NIS 2 resilience plan

The FBI, CISA and HHS updated advisory AA25-071A on 18 August 2026 — 500+ critical infrastructure victims as of April, healthcare hardest hit. The attack pattern — delete backups, encrypt everything, leak stolen data — is a direct test of whether your NIS 2 resilience plan is real or on paper.

Read →
2026-08-18

"Your IT provider has total access: NIS 2 supply-chain obligations after the N-able N-central zero-day"

"Attackers exploited a zero-day in N-able N-central (CVE-2026-18577) and used the MSP platform itself to reach customer systems. Here is what NIS 2 requires Romanian companies to demand from their IT providers — contract clauses, audit rights and privileged-access checks."

Read →
2026-08-11

Three employees, no exploit — what the Levi Strauss breach says about your human risk metrics

Levi Strauss & Co. told the SEC that attackers social-engineered three employees and exfiltrated corporate data. No vulnerability was involved. If your awareness programme reports a healthy phishing click rate and nothing else, it would not have predicted this. Here is what a human risk programme should measure instead.

Read →
2026-07-29

Penetration Testing for Energy and Utilities in Romania — What NIS 2 Requires of Essential Entities

Energy, water and district heating are essential sectors under Romania's OUG 155/2024. That means real testing obligations, fines up to EUR 10 million, and a DNSC that has moved from registration to supervision. Here is how a penetration test is done properly in a mixed IT and OT environment, what gets tested, what is never touched in production, and what the report must contain.

Read →
2026-07-29

Introducing ClickScan — the checks we run by hand, as a product you can run yourself

Keeping what you own online safe should not require a security team. ClickScan is our self-serve, pay-as-you-go scanning platform — the checks our pentesters run by hand, explained in plain language. It launches soon; here is everything it does.

Read →
2026-07-29

When the Attacker Is a Model — What AI-Discovered Zero-Days Do to Your Patching Clock

In one week, OpenAI's own models broke out of a sandbox and reached Hugging Face production, AI agents were credited with a batch of Redis zero-days, and a researcher used AI to turn a Linux race condition into a root exploit. Strip out the hype and one operational fact remains — the time between "a bug exists" and "a working exploit exists" is shrinking. Here is what to change.

Read →
2026-07-20

Critical NGINX Flaw (CVE-2026-42533) — When Your Reverse Proxy Becomes the Target

A critical heap overflow in nginx's regex map handling can crash workers with a single request — and, per one researcher, lead to remote code execution on default Linux builds. Whether you are exposed depends on your configuration, not just your version. Here is how to check, patch and mitigate.

Read →
2026-07-19

wp2shell — An Anonymous Request Can Run Code on Any WordPress Site, No Plugins Needed

wp2shell is a pre-authentication remote code execution chain in WordPress core itself — a bare 6.9 or 7.0 install with zero plugins is exploitable, and a public proof-of-concept is out. Here is what happened, why "we keep our plugins updated" was never the whole story, and what to check today.

Read →
2026-07-14

The Most Common API Security Flaws We Find in Pentests

APIs now carry most of the traffic and most of the risk. Here are the flaws we see again and again during penetration tests, mapped to the OWASP API Security Top 10, plus an illustrative walkthrough of how a "low" file-inclusion bug chains into remote code execution on a .NET service.

Read →
2026-07-14

Does NIS 2 Require Penetration Testing?

NIS 2 never says the word "pentest" — yet for most essential and important entities, penetration testing is the practical way to satisfy Article 21. Here is exactly why, and how often.

Read →
2026-07-10

Device Code Phishing Is Up 37x — The MFA Bypass Your Awareness Training Doesn't Cover

Device code phishing sidesteps passwords, MFA, and even passkeys — because it never touches the login. Detections are up 37x in 2026 as ready-made kits commoditize the technique. Here is how it works, why it beats your current defences, and how to test your staff against it.

Read →
2026-07-09

Poisoned AI Skills and Fake Exploit Repos — The New Supply Chain Attack on Your Team

A fake AI agent skill passed every security scanner and reportedly reached 26,000 agents. A trojanized "proof-of-concept" campaign is hunting the security researchers themselves. The software supply chain now includes the things your AI installs — here is how to defend it.

Read →
2026-07-08

AI Agents Have an Identity Problem — and Attackers Already Know It

Identity management was built around people — an employment record, a manager, a departure date. AI agents have none of those, and they are multiplying across companies faster than anyone is governing them. Practical steps for CISOs and IT managers to get non-human identities under control.

Read →
2026-07-07

The First AI-Run Ransomware Attack — What JADEPUFFER Means for Your Patching Priorities

Sysdig documented JADEPUFFER, an attack it assesses was run end to end by an LLM — breaking in through an old Langflow flaw, harvesting credentials, and wiping a production database. Here is what it changes about how you prioritize patching and exposure.

Read →
2026-07-07

FortiBleed — 110 Million Stolen Credentials, and Why Your Firewall Is the New Crown Jewel

A campaign dubbed FortiBleed targeted 430,000 FortiGate firewalls, harvested over 110 million credentials, and has now been linked to the INC and Lynx ransomware operations. Here is what happened, why edge devices are attackers' favourite way in, and what to do about it this week.

Read →
2026-07-07

Your AI Browser Can Be Talked Into Stealing Your Data — BioShocking and AutoJack Explained

Two new attacks show how AI browsers and agents can be manipulated by a single web page — one convinces the agent it is playing a game, the other turns it into a delivery vehicle for code execution. Should your company allow AI browsers at all? Here is a practical answer.

Read →
2026-07-03

Consent in the Age of AI — and Why Your Company's Data Is Part of the Story

A new free tool, the Human Consent Registry, lets people tell AI systems whether they can use their identity. It is a useful signal for individuals — and a reminder that organizations must control, and secure, the data they feed into AI.

Read →
2026-06-29

NIS 2 and DORA Readiness — A Practical Place to Start

NIS 2 and DORA both raise the bar on cyber risk, incident reporting and accountability. Here is a clear, jargon-free way to see where you stand — plus a free checklist you can download and work through.

Read →
2026-06-27

When More Than 80% of Breaches Start With an Exposed Human

Most incidents no longer begin with a broken firewall — they begin with a person. Here is why human risk is now the decisive control for NIS 2 organizations, and how to manage it as behavior rather than awareness.

Read →
2026-06-25

Pentest vs vulnerability assessment — which do you need?

They are often confused, but they answer different questions. Here is when to use each — and why most teams need both.

Read →
2026-06-20

A 7-point NIS 2 readiness checklist

A practical, no-jargon checklist to gauge how ready your organization is for NIS 2 — and where to start.

Read →